<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSS and IPSEC in the feature in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/css-and-ipsec-in-the-feature/m-p/315874#M5063</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is anything planned that the CSS will support IPSEC in Hardware?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this would only be possible with a new SCM Module. But i do not know if anything is planned out now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i could not find any information, how much IPSEC Tracffic a CSS can handle in Software.&lt;/P&gt;&lt;P&gt;Any information about this would be great. Are we talking about MBit or KBit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is the number of sessions the problem and not the bandwith?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Apr 2005 08:34:22 GMT</pubDate>
    <dc:creator>Sbutzek</dc:creator>
    <dc:date>2005-04-07T08:34:22Z</dc:date>
    <item>
      <title>CSS and IPSEC in the feature</title>
      <link>https://community.cisco.com/t5/application-networking/css-and-ipsec-in-the-feature/m-p/315874#M5063</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is anything planned that the CSS will support IPSEC in Hardware?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think this would only be possible with a new SCM Module. But i do not know if anything is planned out now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also i could not find any information, how much IPSEC Tracffic a CSS can handle in Software.&lt;/P&gt;&lt;P&gt;Any information about this would be great. Are we talking about MBit or KBit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is the number of sessions the problem and not the bandwith?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2005 08:34:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-and-ipsec-in-the-feature/m-p/315874#M5063</guid>
      <dc:creator>Sbutzek</dc:creator>
      <dc:date>2005-04-07T08:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: CSS and IPSEC in the feature</title>
      <link>https://community.cisco.com/t5/application-networking/css-and-ipsec-in-the-feature/m-p/315875#M5064</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the CSS does not support ipsec.&lt;/P&gt;&lt;P&gt;And will never support ipsec.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CSS does SSL in hardware with the CSS5-SSL module.&lt;/P&gt;&lt;P&gt;The module allows you to encrypt/decrypt the SSL traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without the modulem we simply pass SSL traffic like any other TCP traffic.&lt;/P&gt;&lt;P&gt;So this traffic is handled in hardware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We never decrypt/encrypt SSL in software.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 08:47:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-and-ipsec-in-the-feature/m-p/315875#M5064</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-04-07T08:47:49Z</dc:date>
    </item>
    <item>
      <title>Re: CSS and IPSEC in the feature</title>
      <link>https://community.cisco.com/t5/application-networking/css-and-ipsec-in-the-feature/m-p/315876#M5065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Gilles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your quick reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i think, you dit not understand what i mean.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SSL Part i know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But routing IPSEC protocoll over the css occurs in Software not in Hardware like IP traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is, will there be a new generation of css, which changes this. So that IPSEC will be routet in hardware as IP traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My other question was, how much traffic can be handeld via software. I have  no idea if this is in the range of kbit/s or mbit/s or if the limit is the numer of sessions which can be establishd.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CSM is not the coice for me, because it is not as config friendly as the CSS, also i need the Cat6500 as plattform.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;Sven&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 13:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-and-ipsec-in-the-feature/m-p/315876#M5065</guid>
      <dc:creator>Sbutzek</dc:creator>
      <dc:date>2005-04-07T13:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: CSS and IPSEC in the feature</title>
      <link>https://community.cisco.com/t5/application-networking/css-and-ipsec-in-the-feature/m-p/315877#M5066</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sven,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ok - I misunderstood.&lt;/P&gt;&lt;P&gt;IPSEC is routed because this is an unsupported protocol.&lt;/P&gt;&lt;P&gt;So we can't create a flow.&lt;/P&gt;&lt;P&gt;Flow is what we use to switch traffic in hardware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The recommendation is to send this traffic around the CSS with policy routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's difficult to say how much packet we can support.&lt;/P&gt;&lt;P&gt;The problem is the CPU and what it is doing.&lt;/P&gt;&lt;P&gt;If you have lot of keepalives, or L7 rules, or ... your number of packet/sec will be very limited.&lt;/P&gt;&lt;P&gt;If you really want to know how much we can do in software check the white paper for Layer7 performance [this is also done in hardware]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this is a new design, you should really try to not send ipsec traffic through the CSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I said before, we do not plan to support ipsec on the CSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Apr 2005 13:47:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-and-ipsec-in-the-feature/m-p/315877#M5066</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-04-07T13:47:39Z</dc:date>
    </item>
  </channel>
</rss>

